-
Taiwan raids tech firms in China AI chip smuggling probe
-
Online same-sex romance series embrace AI 'freedom'
-
Morocco 'unstoppable' says coach after Netherlands thriller
-
New Oxford academic centre symbolises UK's big-donor era
-
Russia's small businesses pay the price of spiralling Ukraine war
-
Trump says Iran meeting set in Qatar, despite uncertainty
-
Paraguay shock Germany as Brazil, Morocco advance at World Cup
-
Morocco down Netherlands to reach World Cup last 16
-
NASA robot mission aiming to rescue space telescope
-
Asian stocks unable to track Wall St higher, yen holds at 40-year low
-
Mouse-that-roared Paraguay savors World Cup win over Germany
-
'We came from nothing': DR Congo dreams of England World Cup upset
-
Taiwan's ageing seaweed harvesters hope younger women wade in
-
Peruvian political heir Fujimori wins presidency
-
Key Venezuela port opens with US aid, as burials begin
-
What to expect as EU small parcel levy kicks in
-
Ambitious Japan search for answers after World Cup exit
-
Nagelsmann says won't 'run away' after Germany World Cup exit
-
How NATO will try to keep Trump happy at Ankara summit
-
Paraguay coach salutes 'extraordinary' World Cup win over Germany
-
Ultra-wealthy Chinese exile in New York sentenced to 30 years for fraud
-
Japan fans stunned as Brazil end their World Cup dream
-
Years on, families bury 68 Indigenous victims of Guatemala civil war
-
'Powerhouse' Haaland leads by example at World Cup: Norway coach Solbakken
-
'Deliberate' Monaco explosion wounds Ukrainian oligarch
-
Sadness and joy as breakaway Catholic group nears schism
-
Paraguay shock Germany, Brazil advance at World Cup
-
Guardian Metal Resources PLC Announces Pilot Mountain Pre-Feasibility Study Results
-
InterContinental Hotels Group PLC Announces Transaction in Own Shares - June 30
-
Creality Printers Review Site Help Buyers Compare Creality Printers
-
Tenstorrent Sets New Performance Records, Launches TT- Ascalon S, and Expands Across Japan
-
Germany dumped out by Paraguay in seismic World Cup shock
-
'I recognized her ring': identifying Venezuela's dead in a makeshift morgue
-
More than 1,000 drones detected since start of World Cup: FBI
-
Tuchel defensive headache as England ready for DR Congo clash
-
Extreme heat warning issued for World Cup host Kansas City
-
US reopens Venezuela port as quake deaths top 1,700
-
Bloodied but unbowed: Sinner, Djokovic survive Wimbledon scares
-
Coach says Japan getting closer to World Cup glory despite defeat
-
Djokovic battles past Wu in 'challenging' Wimbledon first round
-
NBA Grizzlies deal Morant to Portland: report
-
World Bank drops climate finance targets in renewed action plan
-
Sweden ready for 'game of our lives' in France World Cup clash
-
Ancelotti says never doubted 'suffering' Brazil would score
-
MLS Chicago Fire announce signing of Poland's Lewandowski
-
Venezuela's quake-hit La Guaira port 'operational': US military
-
Tech rebound lifts Dow to record, yen hits 40-year low against dollar
-
Martinelli late show as Brazil down Japan to reach World Cup last 16
-
US Supreme Court rules on dragnet searches of cellphone location data
-
Madueke says he can be England's World Cup game-changer
US arm of China mega-lender ICBC hit by ransomware attack
The US arm of China's largest bank said it was hit by a ransomware attack, forcing clients to reroute trades and disrupting the US Treasury market.
Ransomware attacks typically access vulnerable computer systems and encrypt or steal data, before sending a ransom note demanding payment in exchange for decrypting the data or not releasing it publicly.
The Industrial and Commercial Bank of China Financial Services (ICBC FS) said Thursday it "experienced a ransomware attack that resulted in disruption to certain (financial services) systems."
"Immediately upon discovering the incident, ICBC FS disconnected and isolated impacted systems to contain the incident," the New York-based bank said, adding that it was investigating the attack and working on recovery.
ICBC FS said it had successfully cleared US Treasury trades executed Wednesday and repurchasing (repo) financing trades Thursday.
Slack demand for $24 billion in 30-year US Treasury bonds that were auctioned Thursday came as a surprise to some analysts.
This sale "attracted very poor demand, one of the weakest I can remember," Karl Haeling of the bank LBBW told AFP.
But demand at this sale "might not have been as bad as advertised," said Patrick O'Hare of Briefing.com.
"That's because subsequent reports have indicated that the US financial services division of China's Industrial and Commercial Bank was hit by a ransomware cyberattack yesterday that disrupted trades in the Treasury market."
Richard Flax, chief investment officer at Moneyfarm, put it this way: "Finally, a large Chinese bank suffered a cyber-attack that impacted its ability to trade in US Treasuries. Some commentators argue that that, rather than weak demand, was behind the relatively poor US government bond auction."
Bloomberg reported that some trades handled by ICBC FS on Thursday were transported across Manhattan on a USB stick as messengers manually relayed required settlement details.
China's foreign ministry said Friday that "the business systems and office systems of the head office of ICBC and other domestic and foreign branches and subsidiaries within the group are normal."
"As far as we know, ICBC has paid close attention to this matter, and has done a good job in emergency handling and supervision and communication, striving to minimize the impact of risks and losses," foreign ministry spokesman Wang Wenbin said at a regular news briefing.
"At present, the business systems and office systems of the head office of ICBC and other domestic and foreign branches and subsidiaries within the group are normal."
US media reported that the hack was executed using software created by Lockbit, the Russian-speaking hacking group known for scrambling files on a host's computer and flashing up messages demanding cryptocurrency payment to resolve the issue.
US aircraft manufacturer Boeing was hit with an attack from Lockbit last week.
Last year, LockBit was "the most deployed ransomware variant across the world and continues to be prolific in 2023," according to the US Cybersecurity and Infrastructure Security Agency.
The US Justice Department said in May that LockBit ransomware had been used in more than 1,400 attacks globally.
LockBit has targeted critical infrastructure and large industrial groups, with ransom demands ranging from €5 million to €70 million.
The group attacked Britain's Royal Mail in early January and a Canadian children's hospital in December.
W.Morales--AT